Описание
Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3) id or (4) forum parameter to viewforum.php.
Ссылки
- ExploitVendor Advisory
- Vendor Advisory
- Exploit
- Exploit
- ExploitVendor Advisory
- Vendor Advisory
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:class-1:class-1_forum:0.23.2:*:*:*:*:*:*:*
cpe:2.3:a:class-1:class-1_forum:0.24.4:*:*:*:*:*:*:*
cpe:2.3:a:clever_copy:clever_copy:*:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00752
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3) id or (4) forum parameter to viewforum.php.
EPSS
Процентиль: 73%
0.00752
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other